Cross-site Scripting Vulnerability in WP Thumbtack Review Slider by jgwhite33
CVE-2025-58216

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 August 2025

What is CVE-2025-58216?

An input validation flaw in the WP Thumbtack Review Slider plugin by jgwhite33 enables attackers to exploit stored Cross-site Scripting (XSS) vulnerabilities. This occurs when the plugin improperly handles input during the generation of web pages, allowing malicious scripts to be injected and stored within the application. When executed in the context of a user's session, these scripts can lead to unauthorized actions, data leakage, and compromised user accounts. Affected versions range from n/a up to 2.6, necessitating immediate attention from site administrators to mitigate risks associated with this vulnerability.

Affected Version(s)

WP Thumbtack Review Slider <= 2.6

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vinit Lakra (Patchstack Alliance)
.
CVE-2025-58216 : Cross-site Scripting Vulnerability in WP Thumbtack Review Slider by jgwhite33